Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-6552
Published: June 11, 2026 / Updated: June 12, 2026
Vulnerability details
The vulnerability allows a remote user to take over another user's GitLab account.
The vulnerability exists due to improper access control in group SAML identity management functionality when managing group SAML identities through the Group SAML Identity API. A remote privileged user can exploit authorization flaws to take over another user's GitLab account.
The issue occurs under certain conditions and affects users with the group Owner role.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-6552
GitLab Enterprise Edition - addressed in versions 18.10.8, 18.11.5, 19.0.2